Security Affairs Issues Malware Newsletter 117 Highlighting Lunex Info‑Stealer and Storm‑3168 Cloud Assaults
Security Affairs has published its 117th edition of the Malware Newsletter, a curated roundup of recent research and analysis on malicious software affecting the global cyber landscape.
The issue draws particular attention to Lunex, a newly uncovered information‑stealing tool that spreads through a “bring‑your‑own‑vulnerable‑device” (BYOVD) method, allowing attackers to piggyback on compromised hardware without triggering traditional security alerts.
BYOVD exploits the fact that many organizations connect devices with known weaknesses to their networks, letting malicious code execute under the guise of legitimate firmware. Lunex leverages this gap to harvest credentials, browser data and other personal information before exfiltrating it to command‑and‑control servers.
Another major story in the newsletter is the Storm‑3168 campaign, which employs agentic‑driven attacks against cloud environments. The actors behind Storm‑3168 automate the deployment of malicious agents across multiple cloud tenants, exploiting misconfigurations and weak access controls to gain persistent footholds.
Both threats illustrate a broader shift in cybercrime tactics: adversaries are increasingly favoring stealthier, infrastructure‑borne approaches over overt ransomware strikes. By using existing devices and cloud resources, they can evade detection, scale quickly and reduce the need for custom malware development.
Researchers warn that as BYOVD and cloud‑centric techniques mature, defenders will need to tighten device onboarding procedures, enforce strict configuration baselines and adopt behavior‑based monitoring to spot anomalous activity before data is compromised.
Comments (0)
Be the first to comment.
Join the discussion